Medium severity4.8NVD Advisory· Published Feb 12, 2025· Updated Jun 17, 2026
CVE-2025-1230
CVE-2025-1230
Description
Stored Cross-Site Scripting (XSS) vulnerability in Prestashop 8.1.7, due to the lack of proper validation of user input through ‘/<admin_directory>/index.php’, affecting the ‘link’ parameter. This vulnerability could allow a remote user to send a specially crafted query to an authenticated user and steal their cookie session details.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2= 8.1.7+ 1 more
- (no CPE)range: = 8.1.7
- (no CPE)range: <8.1.7
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.